
Documented security vulnerabilities in the FatFs embedded filesystem library with CVE details, fuzzing harness, exploit disk-image generator, and supply-chain impact analysis across dozens of downstream firmware projects.
This repository documents six confirmed security vulnerabilities in FatFs along with a test harness, fuzzer, and standalone exploit disk-image generator.
The original FatFs source code can be found in the FatFs-R0.16 directory.
This project is a return to a security assessment from 2017, when a manual audit and multi-day fuzzing effort identified some basic, but not interesting bugs in the FatFs driver. Nine years later, in March of 2026, we revisited this project using Visual Studio Code, GitHub Copilot in "auto" mode, and some basic prompts, without any specific loops, harnesses, or skills. The results were surprising - bugs that were overlooked during the manual audit became trivial to find, by using the LLM to automatically build a fuzzer with novel inputs. Not only did this effort find interesting bugs, it also automated the process of validating exploitable across different embedded developent scenarios.
Please see the following files for detailed notes:
FatFs is a portable, royalty-free FAT/exFAT filesystem library written in C by ChaN (elm-chan.org). It is designed for resource-constrained embedded systems with no OS dependency and is typically compiled directly into firmware. It supports FAT12, FAT16, FAT32, and exFAT, as well as optional LFN (Long File Name) and GPT partition support.
Because FatFs is small, self-contained, and permissively licensed, it has
become the de-facto standard FAT implementation for microcontroller firmware.
The library is vendored verbatim into official SDKs, RTOSes, bootloaders, and
application frameworks - meaning a single upstream vulnerability propagates to
every downstream project that copied ff.c.
The following projects have been confirmed to bundle a vulnerable version of FatFs. See 02_CRITICAL.md for the complete analysis, per-project propagation paths, and security contact information.
| Project | Stars | FatFs Version | Bugs |
|---|---|---|---|
| espressif/esp-idf | 17,655 | R0.16 | CVE-2026-6682 |
| STMicroelectronics/stm32-mw-fatfs | all STM32Cube | R0.15 w/p2 | CVE-2026-6682, CVE-2026-6683, CVE-2026-6686, CVE-2026-6687 |
| zephyrproject-rtos/zephyr | 14,820 | R0.16 | CVE-2026-6683, CVE-2026-6687, CVE-2026-6688 |
| micropython/micropython | 21,583 | R0.13c (2019) | CVE-2026-6682, CVE-2026-6683, CVE-2026-6684, CVE-2026-6686, CVE-2026-6687 |
| ArduPilot/ardupilot | 14,743 | R0.14b | CVE-2026-6682, CVE-2026-6683, CVE-2026-6686, CVE-2026-6687 |
| RT-Thread/rt-thread | 11,862 | R0.16 | CVE-2026-6683, CVE-2026-6686 |
| nodemcu/nodemcu-firmware | 7,903 | varies | CVE-2026-6688 |
| RIOT-OS/RIOT | 5,701 | R0.15 | CVE-2026-6682, CVE-2026-6683, CVE-2026-6686, CVE-2026-6687 |
| ARMmbed/mbed-os | 4,837 | R0.14b | CVE-2026-6682, CVE-2026-6683, CVE-2026-6686 |
| sbabic/swupdate | 1,780 | R0.16 | CVE-2026-6683 |
| rsta2/circle | 2,222 | tbd | CVE-2026-6684 |
| hugen79/NanoVNA-H | 695 | R0.15 | CVE-2026-6683 |
| ChibiOS/ChibiOS | 833 | varies | CVE-2026-6688 |
| Samsung/TizenRT | 643 | R0.16 | CVE-2026-6683, CVE-2026-6688 |
| adafruit/tinyuf2 | 447 | tbd | CVE-2026-6684, CVE-2026-6686 |
| grblHAL/Plugin_SD_card | 475 | R0.16 | CVE-2026-6688 |
| JcZou/StarryPilot | 315 | R0.16 | CVE-2026-6688 |
| KeystoneHQ/keystone3-firmware | 199 | R0.16 | CVE-2026-6682 |
| flysight/flysight | 44 | varies | CVE-2026-6682, CVE-2026-6688 |
| eugene-tarassov/vivado-risc-v | 1,061 | tbd | CVE-2026-6684 |
| CVE ID | Short Title | CWE |
|---|---|---|
| CVE-2026-6682 | Integer Overflow in FAT32 Volume Mount | CWE-190: Integer Overflow or Wraparound |
| CVE-2026-6683 | Divide-by-Zero in exFAT Sync | CWE-369: Divide By Zero |
| CVE-2026-6684 | Infinite Loop in GPT Partition Scan | CWE-835: Loop with Unreachable Exit Condition |
| CVE-2026-6686 | Use of Uninitialized Clusters After Seek Past EOF | CWE-908: Use of Uninitialized Resource |
| CVE-2026-6687 | Stack Buffer Overflow via Uncapped exFAT Label Length | CWE-121: Stack-based Buffer Overflow |
| CVE-2026-6688 | Buffer Overflow via Unbounded LFN Filename Copy | CWE-120: Buffer Copy without Checking Size of Input |
FatFs has no CVE history, no security mailing list, and no patch notification
mechanism. Every downstream project that vendors ff.c must discover, triage,
and patch these vulnerabilities independently, usually without knowing they are
affected. That means the window between public disclosure and widespread
remediation will be measured in years, not days. The practical attack surface
is therefore not one software application or serbvice, but tens of millions of
devices across dozens of independent codebases, many of which will never receive
a patch.
The archetypal exploitation scenario is the evil SD card: an attacker with a few seconds of physical access swaps the storage medium in a device, from consumer cameras to drones, to 3-D printers to a thousand other product families. Every vulnerability in this set is triggerable by mounting a crafted FAT image, which nearly always happens automatically on insertion with no user interaction required. That said, physical access is not the only path.
Devices that ingest FAT-formatted update packages from a network source such as OTA update frameworks and drag-and-drop bootloader updates, are exploitable by any attacker who can deliver a malicious image to the update pipeline. Supply chain compromises, an AitM injection on a cleartext HTTP update feed, or a malicious image posted to a hobby firmware distribution portal. The OTA path is fully remote on any device that lacks end-to-end authenticated integrity verification of its update container prior to mounting it with FatFs.
CVE-2026-6682 - Integer overflow leading to attacker-controlled read length